CVE-2016-8375 Details
Description
An issue was discovered in Becton, Dickinson and Company (BD) Alaris 8015 Point of Care (PC) unit, Version 9.5 and prior versions, and Version 9.7, and 8000 PC unit. An unauthorized user with physical access to an affected Alaris PC unit may be able to obtain unencrypted wireless network authentication credentials and other sensitive technical data by disassembling the PC unit and accessing the device's flash memory. The Alaris 8015 PC unit, Version 9.7, and the 8000 PC unit store wireless network authentication credentials and other sensitive technical data on internal flash memory. Accessing the internal flash memory of the affected device would require special tools to extract data and carrying out this attack at a healthcare facility would increase the likelihood of detection.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://ics-cert.us-cert.gov/advisories/ICSMA-17-017-01 | CVE | MitigationThird Party AdvisoryUS Government Resource |
| https://ics-cert.us-cert.gov/advisories/ICSMA-17-017-02 | CVE | MitigationThird Party AdvisoryUS Government Resource |
| http://www.securityfocus.com/bid/96113 | CVE | Third Party AdvisoryVDB Entry |
| https://ics-cert.us-cert.gov/advisories/ICSMA-17-017-01 | [email protected] | MitigationThird Party AdvisoryUS Government Resource |
| https://ics-cert.us-cert.gov/advisories/ICSMA-17-017-02 | [email protected] | MitigationThird Party AdvisoryUS Government Resource |
| http://www.securityfocus.com/bid/96113 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-255 | Credentials Management Errors | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| bd alaris 8015 pc unit | <= 9.5 9.7 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 13, 2026 | CVE Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Mar 16, 2017 | Initial Analysis | [email protected] |
| Feb 15, 2017 | CVE Modified | [email protected] |
| Feb 14, 2017 | CVE Modified | [email protected] |